4 ms·
The exploit page (the one the victim is supposed to click on) loads the injected page (in this case Yahoo Mail) as stylesheet. The CSS parser throws away all th
by danielh 17y ago
The exploit page (the one the victim is supposed to click on) loads the injected page (in this case Yahoo Mail) as stylesheet. The CSS parser throws away all the html and correctly parses the injected css.
I think the description is not very clear about this step, I had to look at the source of the exploit page to understand what happens.
- jrockway 17y agoClever. But if the single quotes were ", and so on, this would not work. CSS does not have SGML entity support (or does it? please tell me it doesn't...)